Privacy Policy

Version 1.0. Effective 14 September 2026.

This Privacy Policy explains how we handle personal information. It is written to comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

Who we are. The Service is operated by Axiom Tools, ABN 30 132 181 813 (“we”, “us”, “our”), a sole trader business. The individual who holds that ABN is the entity responsible for your personal information, and can be identified through the Australian Business Register at abr.business.gov.au. We are an online business, and the way to reach us is by email: privacy@axiomtools.au for privacy matters, or support@axiomtools.au for anything else.

What “the Service” means. The Service is the marketing content and scheduling service we provide at axiomtools.au: it generates draft marketing copy using AI, schedules it, and publishes content you have approved to social media accounts you connect.

By using the Service you agree to this Policy. If you do not agree, do not use the Service.


1. Information We Collect

Account information. Your email address, name, timezone, and a password hash. We never store your password in a readable form.

Business information you provide. Your business description, audience, offer, differentiator, tone, banned phrases, competitor names, website and product URLs. These fields are freeform and you may type anything into them.

Please do not enter sensitive information as defined in the Privacy Act 1988 (Cth), including health information, into your brand description or any other free text field. These fields are used to generate marketing copy and their contents are sent to our AI subprocessor.

Connected account credentials. OAuth access tokens and refresh tokens for the social media accounts you connect, together with the account identifiers and display names of those accounts. For X, this also includes the API credentials you supply from your own X developer account.

Content. The marketing copy generated for you, your edits to it, scheduling information, and your approval decisions.

Performance data. Aggregate engagement counts for posts published through the Service: impressions or views, reactions or likes, comment counts, shares, clicks, and saves. Counts only — see section 6.

Billing information. Handled by Stripe. We store a Stripe customer identifier and your subscription status. We never see or store your card number.

Usage data. Log data, IP address, browser and device information, and feature usage.

Support and privacy correspondence. Emails you send to support@axiomtools.au or privacy@axiomtools.au, our replies, and whatever you choose to put in them.

We do not knowingly collect information about persons under the age of 18.


2. How We Collect Information

We collect information in four ways:

We collect data from social platforms only through their official APIs, and only under the permissions you granted when you connected the account. You can revoke those permissions at any time, either from the Connections screen in the app or from the platform’s own application settings.


3. Purpose of Collection and Use

We use your information to:

Content is published only after you have reviewed and approved it. The Service does not publish content you have not seen.


4. Disclosure of Personal Information

We disclose personal information to the following recipients, and only for the purposes described:

RecipientWhat they receiveWhy
Anthropic (Claude API)Your business information, the content of your posts, and aggregate performance figuresTo generate and analyse marketing copy. Acts as our subprocessor
SupabaseAccount information, business information, content, and performance dataDatabase and authentication hosting
Fly.ioData in transit through the application, including request payloadsApplication hosting
StripeBilling informationPayment processing
The social platforms you connectThe content you approve for publishing, and the requests we make to retrieve performance data on those postsBecause publishing to them is the purpose of the Service
Professional advisers, and law enforcement or regulatorsOnly what is necessary or requiredWhere we are legally required or permitted to disclose

Anthropic does not train its models on data submitted through its API.

We do not sell your personal information. We do not share it with advertisers or data brokers. We do not use your business information or your content to train AI models, and our AI subprocessor does not train on data submitted through its API.


5. Your Content and Your Connected Accounts

Ownership. You own your business information and your content. We process it to provide the Service and for nothing else.

Access tokens. When you connect a social account you grant us an access token. That token lets us publish content you have approved to that account, and retrieve aggregate performance data on those posts. It does not let us, and we do not use it to, read your private messages or your personal feed. Tokens are encrypted at rest and are decrypted only in memory, at the moment an API call is made. Disconnecting an account deletes its stored tokens immediately.

Which accounts we publish to automatically. The Service publishes automatically to Facebook Pages, Instagram, TikTok, and X. For LinkedIn, Reddit, Hacker News and Product Hunt the Service writes the copy and you publish it yourself; we hold no credentials for those platforms and make no API calls to them on your behalf.

Your own X credentials. X is connected using API credentials you create and supply from your own X developer account. Your relationship and your contract with X are yours, not ours, and any fees X charges are billed to you by X directly.

Publishing in your name. Content publishes to your accounts under your identity, not ours. Readers see it as your business posting. You are responsible for the content you approve. We generate drafts; you decide what goes out.

AI-generated content. Copy is generated by an AI model from the information you provide. It may contain errors, and it may make claims about your business that are not correct. You review everything before it publishes and you are responsible for its accuracy.

Revocation. You may disconnect any account at any time, from our Connections screen or from the platform’s own application settings. Disconnecting stops all future publishing to that account and deletes the stored tokens. Content already published stays published, because it is held by the platform and not by us; you remove it there.


6. Information About Other People

When we retrieve performance data for posts published through the Service, we collect aggregate counts only: the number of impressions, reactions, comments, shares, and clicks a post received.

We do not collect, store, or display the content of comments. We do not collect, store, or display the names, profile information, images, or any other personal information of the people who view, react to, comment on, or share your posts.

This is a design constraint of the system, not a current setting. There is no facility in the product to store this information.


7. Data Security

We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure:

No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

Data breaches. We handle data breaches under the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act 1988 (Cth).

If we have reasonable grounds to suspect that an eligible data breach may have occurred, we will carry out a reasonable and expeditious assessment of whether it has, and we will complete that assessment within 30 days of becoming aware of the grounds for suspicion.

If we have reasonable grounds to believe that an eligible data breach has occurred — meaning unauthorised access to, unauthorised disclosure of, or loss of personal information we hold, that is likely to result in serious harm — we will notify the Office of the Australian Information Commissioner (“OAIC”) and the individuals at risk of serious harm as soon as practicable.

Where we are able to take remedial action quickly enough that serious harm is no longer likely, the scheme does not treat the incident as an eligible data breach requiring notification.


8. Data Retention

We retain personal information only for as long as we need it.

DataRetention
OAuth tokens and supplied API credentialsUntil you disconnect the account or delete your account, then deleted immediately
Account informationLife of the account, then deleted within 30 days
Business information and contentLife of the account, then deleted within 30 days
Performance dataLife of the account, then deleted within 30 days
Billing records7 years, as required by Australian taxation law
Usage data and server logsHeld by our application host on a rolling window of roughly a week, then discarded. We do not export them or keep a copy of our own
Support and privacy correspondence24 months after the matter is resolved
BackupsPurged within 90 days

Deleting your account. You can delete your account from within the app at any time. Deletion removes your account information, business information, content, performance data, and all stored credentials, subject to the billing records we are required to keep. See our Data Deletion page for the full instructions and for how to make a deletion request if you can no longer sign in.

On account closure or on a deletion request, we delete or de-identify your personal information within 30 days, except where we are required to retain it by law or need it for the establishment, exercise, or defence of a legal claim.

Where you ask us to delete your data by email, we will confirm in writing by email once it is done. Deleting your account from within the app happens immediately and sends no confirmation email: the account is gone when the screen says it is.

Backups. Deleted data may persist in encrypted backups before those backups are purged. During that period the data is not actively used, is not reachable through the Service, and is protected the same way active data is.

We also operate an endpoint that accepts platform-initiated deletion requests, so that removing our application from your social account also removes the connection data we hold for it.


9. Cookies and Tracking Technologies

We use cookies and browser storage only to keep you signed in and to hold your session. We do not use advertising cookies, tracking pixels, or third-party analytics on the Service.

Blocking these cookies will prevent you from signing in.


10. Your Rights

Under the Privacy Act 1988 (Cth) you may:

Most of these you can do yourself in the app. For anything else, contact us at privacy@axiomtools.au. We will respond within 30 days. We do not charge for access requests, and if we refuse access or correction we will tell you why in writing.

Automated decision-making. The Service makes automated decisions on your behalf: it decides what content to draft, which platform to draft it for, and when to schedule it. These decisions are made from the information in your own account. No content is published without your approval, and you can edit, reschedule, or cancel anything that has not yet published.


11. Direct Marketing

We may send you emails about the Service, including service announcements and billing notices. Service and billing messages are part of providing the Service and you cannot opt out of them while you hold an account.

We do not email you about your content. A post that failed to publish, a connection that has stopped working, and a manual post that is overdue are shown to you in the app and nowhere else. The Service sends no email, SMS, or push notification about them.

We may also send you occasional emails about features and offers. You can opt out of those at any time using the unsubscribe link in the email, or by contacting privacy@axiomtools.au. We do not sell or provide your information to third parties for their own direct marketing.


12. Third-Party Links and Services

The Service links to third-party websites and integrates with third-party platforms. We are not responsible for their content or their privacy practices.

This applies with particular force to the social platforms you connect. Once content is published to a platform, that platform holds it, and that platform’s own privacy policy governs what it does with it. The same is true of the engagement data those platforms hold about the people who interact with your posts, which we do not receive and do not store. Read the privacy policy of each platform you connect.


13. Overseas Disclosure (APP 8)

Your account information, business information, content, and performance data are stored in Australia, in the Sydney region of our database provider’s infrastructure. Our application servers are also located in Sydney.

Where your data sits and who can reach it are two different questions, and this section answers both. Supabase and Fly.io hold and process your data in Sydney, but both are United States companies whose personnel may be able to reach the systems holding it in the course of support and maintenance. We treat that as an overseas disclosure and list them below, rather than relying on the data’s location alone.

We disclose information to the following overseas recipients:

RecipientLocationWhat they receive
SupabaseData stored in Sydney; company and personnel in the United StatesAccount information, business information, content, and performance data
Fly.ioData processed in Sydney; company and personnel in the United StatesData in transit through the application, including request payloads
AnthropicUnited StatesYour business information, the content of your posts, and aggregate performance figures, for generating and analysing marketing copy
StripeUnited StatesBilling information, for payment processing
The social platforms you connectVaries by platformThe content you approve for publishing, and the requests we make to retrieve performance data on those posts

By connecting a social platform you direct us to send your approved content to that platform, which may store and process it anywhere it operates. Each platform’s own privacy policy governs what it does with that content once published.

Where personal information is disclosed to an overseas recipient, we take reasonable steps to ensure that the overseas recipient does not breach the Australian Privacy Principles in relation to that information, as required by APP 8.1. Our reasonable steps are:

The social platforms you connect are a different case. You direct that disclosure by connecting the account, we rely on no certification of theirs, and each platform’s own privacy policy governs what it does with your content once published.

You acknowledge that an overseas recipient may not be subject to the Privacy Act 1988 (Cth) or the Australian Privacy Principles, that the laws of the recipient’s country may differ from Australian privacy law, and that you may have limited ability to seek redress under the Privacy Act 1988 (Cth) in respect of an act or practice of an overseas recipient.


14. Changes to This Policy

We may update this Policy from time to time. Where a change is material we will notify you by email or through the app before it takes effect. The version number and effective date at the top of this page tell you which version applies.


15. Complaints

If you believe we have breached the Australian Privacy Principles, contact us at privacy@axiomtools.au with the details.

We will acknowledge your complaint within 5 business days and aim to resolve it within 30 days. If we need longer we will tell you why and when to expect an answer.

If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner:


16. Contact Information

Axiom Tools ABN 30 132 181 813

We are an online business and take all contact by email.

Privacy enquiries: privacy@axiomtools.au
General support: support@axiomtools.au


17. Relationship to the Terms of Service

This Policy forms part of our Terms of Service. Where this Policy describes how we handle personal information, it prevails over anything inconsistent in the Terms.